South Korea's president warns of AI-assisted bank hacks. Shinhan faces a formal inspection after data on 25,700 customers leaked.

South Korean President Lee Jae-myung, over a headline on AI-assisted bank hacking

Cover photo: The White House, public domain.

Key points

  • The president called for urgent action
  • Shinhan now faces a formal inspection
  • Internet banks blocked attempts from the same addresses

On October 6, President Lee Jae-myung (이재명) called for urgent action over Korea's bank breaches at a cabinet meeting at the Blue House. He said some of the attacks had used AI, and warned that the technology could make hacking easier for anyone.

"Some of this hacking turned out to use AI, so the public's worry and unease are very high," the president said. "Now anyone can hack easily with AI, even without any special skill." He told the agencies involved to put people and resources into keeping the damage as small as possible.

I wrote a few days ago about the breach at seven Korean lenders, where a security researcher found the name of a free AI hacking tool on one of the attack servers. What's new is how far it has traveled in a week. It has the president's attention now, the police have opened a formal case, and one of the country's biggest banks is under formal inspection.

Shinhan now faces a formal inspection

Shinhan Bank (신한은행) is the hardest hit of the country's big banks. The bank lost information on about 25,700 customers. The stolen data included names, phone numbers, yearly income and loan limits. It also held resident registration numbers, Korea's national ID numbers, for 66 customers, and a linked identification code known as CI for 97 customers.

On October 6 the Financial Supervisory Service (금융감독원) moved from a field check to a formal on-site inspection. That change matters. Until now the regulator was gathering facts, and now it's looking into whether Shinhan broke the law. The attackers got in through a mobile site for loan brokers called M Shinhan, not through the app that customers use.

Regulators traced the attacks to 28 addresses in 12 countries

The regulator shared 33 attack internet addresses, 28 of them unique, with the rest of the industry. The addresses sat in 12 countries, and the United States had the most at five. The agency warned that an address doesn't prove where an attacker really is, because a hacker can route through many places on the way in.

In my earlier piece the count was eight countries. Six days later it's 12, which is a sign the picture is still filling in. The regulator also put out a consumer alert at the "caution" level and set up a one-month special period to watch for second-round harm, like scam calls. Someone who knows your name, phone number, income and loan limit can call as if they already handle your loan.

Internet banks blocked attempts from the same attack addresses

The attack addresses didn't only hit the regular banks. Some of the addresses used in the earlier attacks also reached the servers of Kakao Bank (카카오뱅크) and K bank (케이뱅크), and Toss Bank (토스뱅크) saw attempts going back to January. All three said they blocked the attempts and reported no customer data leaks.

Why did they hold when the big banks didn't? Regulators point to two things. The internet banks ask for more than an ID and a password before they let someone in, and they have fewer side systems hanging off the open internet. That fits the pattern from the start of this story. The hackers kept going after the loan-broker and staff systems on the edge, not the core banking that people use every day.

Lee orders urgent checks of the country's core systems

President Lee didn't stop at the banks. He told his ministers to check the security of the nation's core systems, not just private companies, and to make the fixes right away. "Speed is everything," he said. He also asked the government to speed up building AI made for cybersecurity, since the same kind of technology the attackers lean on can be turned around to defend.

The police have moved as well. The National Office of Investigation booked the case under the Information and Communications Network Act and put its cyber unit on it full time. The financial regulator has also ordered financial firms to conduct emergency security checks.

Meanwhile, Shinhan says it will fully compensate customers for losses caused by the leak. The question now is how customers will document those losses and how the bank will assess their claims.

The president's comments are translated from Korean.

Frequently asked questions

What did President Lee Jae-myung say about Korea's bank hacking?

At a cabinet meeting at the Blue House on October 6, President Lee Jae-myung said some of the attacks had used AI and that public worry was very high. He said anyone can now hack easily with AI, even without special skills. He told his ministers to check the security of the nation's core systems, make the fixes right away, and speed up building AI made for cybersecurity. His comments are translated from Korean.

How many Shinhan Bank customers had their data stolen?

About 25,700. The stolen data included names, phone numbers, yearly income and loan limits. For 66 customers it also held resident registration numbers, which are Korea's national ID numbers, and for 97 it held a linked identification code known as CI. On October 6 the Financial Supervisory Service moved to a formal on-site inspection of Shinhan.

Did the hackers get into Korea's internet banks?

No. Some of the addresses used in the earlier attacks also reached the servers of Kakao Bank and K bank, and Toss Bank saw attempts going back to January, but all three said they blocked the attempts and reported no customer data leaks. Regulators credit stronger log-in checks and fewer systems exposed to the open internet.

How many internet addresses and countries were involved?

The Financial Supervisory Service shared 33 attack internet addresses, 28 of them unique, across 12 countries, with the United States the most common at five. It warned that an address does not prove where an attacker really is, because a hacker can route through many places.

More on 055550 and 105560

Mia Park
Mia Park

Mia Park was born and raised in Korea and covers its markets and business news for AIStockWire, from the Kospi and Kosdaq to Samsung, SK Hynix, and the companies shaping the country's technology sector. She got her start writing for a Korean entertainment blog, a long way from stock filings, but has always enjoyed knowing what is happening back home before everyone else does.